US officials work with Crowd
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
US federal law enforcement, collaborating with cybersecurity firm CrowdStrike and international partners, disrupted the Sality botnet and its associated malware. This malware enabled theft of approximately $150,000 in cryptocurrency by replacing copied wallet addresses with those controlled by the operators. The effort involved officials from Bulgaria, Hungary, Romania, CrowdStrike, and the Shadowserver Foundation.
Why it matters
The source indicates this action stopped ongoing theft and cyberattacks linked to the Sality botnet, affecting thousands of infected computers worldwide. The disruption prevents further unauthorized redirection of crypto payments, safeguarding users' digital assets. The article does not explicitly elaborate on broader market or policy implications.
Key context
Sality has been installing malware on devices since 2003, creating a peer-to-peer botnet with about 15,000 infected machines. Over the past eight years, the operators used EggJagger, a clipboard hijacking tool, to stealthily redirect cryptocurrency payments by swapping wallet addresses. The botnet checked in with its control network every 40 minutes until authorities disrupted its communication ability.
Key numbers and entities
The DOJ, CrowdStrike, Shadowserver Foundation, and authorities from Bulgaria, Hungary, and Romania are involved. The malware stole at least 12.1 million rubles (around $150,000), with the maximum value of the digital assets reaching $1.5 million in January 2025. Approximately 15,000 computers were part of the Sality botnet.
What remains unclear
The source does not specify the identities of the individuals or groups behind Sality. It also does not detail the timeline or mechanics of the botnet disruption beyond the general statement of lost communication with infected machines. Further information on potential legal outcomes or preventive measures was not provided.